Privacy statement
Last updated 6 October 2026
Nimbu Global Pty Ltd t/a Nimbu Creative (ABN 68 642 716 452), referred to here as "we", "us" or "our", respects your privacy. This statement explains how we collect, use, share and protect personal information through our proposals system at proposals.nimbuops.dev, including our discovery form and our online proposals.
We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth).
What we collect
- Discovery form: your name, business name, email address and phone number; information about your business, your customers and your current website; what you want your new website to do; websites you like; your timing and budget; how you found us; and anything else you choose to tell us.
- Discovery sessions: notes we make while discussing your project with you, such as your domain, hosting and email arrangements and the integrations you need.
- Proposals: when you view, comment on or accept a proposal, the options you choose, any comments you leave, and your acceptance details: your name, position, company name, ABN, typed signature, and the date and time of acceptance.
- Technical information: your IP address, browser and device type, and the dates and times you open your proposal. We use this to protect the system and to keep a reliable record of acceptance.
- Payments: payments are taken by Stripe on its own secure pages. We never receive or store your card or bank account details. Stripe tells us whether a payment succeeded, the amount and a reference number.
Please do not send us sensitive information, such as health information, through the discovery form or proposal comments. We do not need it to prepare a proposal.
How we use it
- To respond to your enquiry and arrange a discovery session.
- To prepare, send and follow up your proposal, including reminders before it expires.
- To record your acceptance and send you a copy of the accepted proposal.
- To take payments and issue invoices and receipts.
- To deliver your project and keep in touch with you while we work on it.
- To keep business, accounting and tax records.
- To protect our systems from misuse and fraud.
We contact you about your enquiry, your proposal and your project. We do not add you to marketing lists without your agreement, and we never sell personal information.
Who we share it with
We share personal information only as needed for the purposes above, with:
- our team members who work on your enquiry or project;
- service providers who run parts of the system for us: Cloudflare (hosting, security, database and file storage), SMTP2GO (email delivery), Stripe (payments), Xero (invoicing and accounting) and Microsoft (Microsoft 365 and SharePoint, where we keep project records);
- our professional advisers, such as our accountant or lawyers, where needed; and
- government bodies, regulators or law enforcement where the law requires or allows it.
Information stored outside Australia
Some of our service providers store or process information outside Australia, including in the United States and other countries where they operate data centres. We choose established providers that commit to protecting the information they hold and take reasonable steps to make sure they handle it consistently with the Australian Privacy Principles.
How we protect it
The system uses encrypted connections. Only our team can reach the admin area, and signing in needs multi-factor authentication. Each proposal link is unique, hard to guess, expires on the proposal's validity date and can be cancelled by us at any time. Please do not forward your proposal link to people who should not see it.
How long we keep it
We keep accepted proposals, acceptance records, invoices and payment records for at least five years, as required for tax records, and longer while we have an ongoing working relationship with you. Enquiries and proposals that do not go ahead are kept only as long as reasonably needed and are then deleted or de-identified.
Cookies
Our proposal pages do not use advertising or tracking cookies. Cloudflare may set cookies that are strictly necessary for security and bot protection, including on the discovery form.
Accessing and correcting your information
You can ask to see the personal information we hold about you, or ask us to correct it, by contacting us using the details below. We will respond within a reasonable time, usually within 30 days. If we cannot give you access, we will explain why.
Questions and complaints
If you have a question or concern about how we have handled your personal information, please contact us first and we will respond within 30 days. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner at www.oaic.gov.au or on 1300 363 992.
Governing law
This statement is governed by the laws of Western Australia and the applicable laws of the Commonwealth of Australia.
Changes to this statement
We may update this statement from time to time. The current version is always on this page, with the date it was last updated.
Contact us
Nimbu Creative
Email: create@nimbucreative.com
Phone: 08 6115 0345